| 1.1 | CVE-2026-0302
Checkov by Prisma Cloud: OS Command Injection Vulnerability | Checkov by Prisma Cloud 3.2.0 | | | 2026-09-09 | 2026-09-09 |
| 7.2 | CVE-2026-0310
PAN-OS: Buffer Overflow Vulnerability via XML Processing | Cloud NGFW PAN-OS 12.2 PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access 12.1 Prisma Access 11.2 Prisma Access 10.2 | All on AWS*, All on Azure* < 12.2.3 < 12.1.4-h10, < 12.1.7-h5, < 12.1.10 < 11.2.4-h21, < 11.2.7-h20, < 11.2.10-h14, < 11.2.13-h2 < 11.1.4-h36, < 11.1.6-h38, < 11.1.7-h10, < 11.1.10-h33, < 11.1.13-h12, < 11.1.16-h2 < 10.2.7-h37, < 10.2.10-h40, < 10.2.13-h24, < 10.2.16-h10, < 10.2.18-h10 < 12.1.7-h5* < 11.2.7-h20* < 10.2.10-h40* | None on AWS*, None on Azure* >= 12.2.3 >= 12.1.4-h10, >= 12.1.7-h5, >= 12.1.10 >= 11.2.4-h21, >= 11.2.7-h20, >= 11.2.10-h14, >= 11.2.13-h2 >= 11.1.4-h36, >= 11.1.6-h38, >= 11.1.7-h10, >= 11.1.10-h33, >= 11.1.13-h12, >= 11.1.16-h2 >= 10.2.7-h37, >= 10.2.10-h40, >= 10.2.13-h24, >= 10.2.16-h10, >= 10.2.18-h10 >= 12.1.7-h5* >= 11.2.7-h20* >= 10.2.10-h40* | 2026-09-09 | 2026-09-09 |
| 2.4 | CVE-2026-0303
Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File | Checkov by Prisma Cloud 3.2.0 | | | 2026-09-09 | 2026-09-09 |
| 5.8 | CVE-2026-0306
Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows | Prisma Access Agent Prisma Access Agent 0 | None on Linux, None on macOS, None on iOS, None on Android, None on ChromeOS < 26.2 on Windows | All on Linux, All on macOS, All on iOS, All on Android, All on ChromeOS >= 26.2 on Windows | 2026-09-09 | 2026-09-09 |
| 7.7 | PAN-SA-2026-0012
Chromium: Monthly Vulnerability Update (September 2026) | | | | 2026-09-09 | 2026-09-09 |
| 5.9 | CVE-2026-0307
GlobalProtect App: Local Privilege Escalation Vulnerabilities | GlobalProtect App GlobalProtect App 6.3 GlobalProtect App 6.2 GlobalProtect App 6.0 | None on iOS, None on Android, None on ChromeOS < 6.3.3-h15 on Linux (ETA: 09/17), < 6.3.3-h15 on macOS (ETA: 09/28), < 6.3.3-h15 on Windows (ETA: 09/28) < 6.2.8-h14 on macOS, < 6.2.8-h14 on Windows < 6.0.15 on Linux (ETA: 09/28), < 6.0.15 on macOS (ETA: 09/28), < 6.0.15 on Windows (ETA: 10/29) | All on iOS, All on Android, All on ChromeOS >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h15 on macOS (ETA: 09/28), >= 6.3.3-h15 on Windows (ETA: 09/28) >= 6.2.8-h14 on macOS, >= 6.2.8-h14 on Windows >= 6.0.15 on Linux (ETA: 09/28), >= 6.0.15 on macOS (ETA: 09/28), >= 6.0.15 on Windows (ETA: 10/29) | 2026-09-09 | 2026-09-09 |
| 4.8 | CVE-2026-0304
Cortex XDR Broker VM: Privilege Escalation Vulnerability | Cortex XDR Broker VM 20.0.96 | | | 2026-09-09 | 2026-09-09 |
| 4.1 | CVE-2026-0295
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS | GlobalProtect App GlobalProtect App 6.3 GlobalProtect App 6.2 GlobalProtect App 6.0 | None on Linux, None on Windows, None on iOS, None on Android, None on Chrome OS < 6.3.3-h14 (6.3.3-1121) on macOS < 6.2.8-h13 (6.2.8-1045) on macOS < 6.0.15 on macOS | All on Linux, All on Windows, All on iOS, All on Android, All on Chrome OS >= 6.3.3-h14 (6.3.3-1121) on macOS >= 6.2.8-h13 (6.2.8-1045) on macOS >= 6.0.15 on macOS (ETA: 08/31) | 2026-08-12 | 2026-08-12 |
| 1.7 | CVE-2026-0301
PAN-OS: Information Disclosure Vulnerability in URL Filtering | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access 12.1 Prisma Access 11.2 Prisma Access 10.2 | All on AWS*, All on Azure* None None < 11.1.16-h1 < 10.2.8 None None < 10.2.10 | None on AWS*, None on Azure* All All >= 11.1.16-h1 >= 10.2.8 All All >= 10.2.10 | 2026-08-12 | 2026-08-12 |
| 5.2 | CVE-2026-0298
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) | GlobalProtect App GlobalProtect App 6.3 GlobalProtect App 6.2 GlobalProtect App 6.0 | None on Linux, None on macOS, None on Android, None on Chrome OS, None on iOS < 6.3.3-h14 (6.3.3-1121) on Windows < 6.2.8-h13 (6.2.8-1045) on Windows < 6.0.15 on Windows (ETA: 08/31) | All on Linux, All on macOS, All on Android, All on Chrome OS, All on iOS >= 6.3.3-h14 (6.3.3-1121) on Windows >= 6.2.8-h13 (6.2.8-1045) on Windows >= 6.0.15 on Windows (ETA: 08/31) | 2026-08-12 | 2026-08-12 |
| 5.2 | CVE-2026-0297
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake | GlobalProtect App 6.3 GlobalProtect App 6.2 GlobalProtect App 6.0 | < 6.3.3-h15 on Linux, < 6.3.3-h14 (6.3.3-1121) on macOS, < 6.3.3-h14 (6.3.3-1121) on Windows, < 6.3.5 on iOS, < 6.3.5 on Android, < 6.3.5 on Chrome OS All on Linux, < 6.2.8-h13 (6.2.8-1045) on macOS, < 6.2.8-h13 (6.2.8-1045) on Windows < 6.0.15 on Linux, < 6.0.15 on macOS, < 6.0.15 on Windows, < 6.0.15 on iOS, < 6.0.15 on Android, < 6.0.15 on Chrome OS | >= 6.3.3-h15 on Linux (ETA: 08/28), >= 6.3.3-h14 (6.3.3-1121) on macOS, >= 6.3.3-h14 (6.3.3-1121) on Windows, >= 6.3.5 on iOS (ETA: 08/24), >= 6.3.5 on Android (ETA: 08/18), >= 6.3.5 on Chrome OS (ETA: 08/18) None on Linux, >= 6.2.8-h13 (6.2.8-1045) on macOS, >= 6.2.8-h13 (6.2.8-1045) on Windows >= 6.0.15 on Linux (ETA: 08/31), >= 6.0.15 on macOS (ETA: 08/31), >= 6.0.15 on Windows (ETA: 08/31), >= 6.0.15 on iOS (ETA: 08/31), >= 6.0.15 on Android (ETA: 08/31), >= 6.0.15 on Chrome OS (ETA: 08/31) | 2026-08-12 | 2026-08-12 |
| 7.2 | PAN-SA-2026-0011
Chromium: Monthly Vulnerability Update (August 2026) | | | | 2026-08-12 | 2026-08-12 |
| 5.8 | CVE-2026-0278
Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows | Prisma Access Agent Prisma Access Agent 0 | None on macOS < 26.2.1 on Windows | All on macOS >= 26.2.1 on Windows | 2026-07-08 | 2026-07-08 |
| 1.1 | CVE-2026-0276
Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability | Cortex XDR Broker VM 20.0.96 | | | 2026-07-08 | 2026-07-08 |
| 7.2 | PAN-SA-2026-0010
Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) | | | | 2026-07-08 | 2026-07-08 |
| 4.4 | CVE-2026-0268
Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux | Prisma Access Agent Prisma Access Agent | None on Windows, None on macOS, None on iOS, None on Android, None on Chrome OS < 26.2.1 on Linux | All on Windows, All on macOS, All on iOS, All on Android, All on Chrome OS >= 26.2.1 on Linux | 2026-06-10 | 2026-06-10 |
| 8.4 | PAN-SA-2026-0008
Chromium: Monthly Vulnerability Update (June 2026) | | | | 2026-06-10 | 2026-06-10 |
| 1.1 | CVE-2026-0238
Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields | | | | 2026-05-13 | 2026-05-13 |
| 5.1 | CVE-2026-0241
Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities | Trust Protection Foundation 25.3.0 Trust Protection Foundation 25.1.0 Trust Protection Foundation 24.3.0 Trust Protection Foundation 24.1.0 | < 25.3.3 < 25.1.8 < 24.3.6 < 24.1.13 | >= 25.3.3 >= 25.1.8 >= 24.3.6 >= 24.1.13 | 2026-05-13 | 2026-05-13 |
| 6.1 | PAN-SA-2026-0007
Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026) | | | | 2026-05-13 | 2026-05-13 |
| 4.9 | CVE-2026-0239
Chronosphere Chronocollector Information Disclosure Vulnerability | Chronosphere Chronocollector | | | 2026-05-13 | 2026-05-13 |
| 7.2 | CVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled | Cloud NGFW PAN-OS 12.1 PAN-OS 11.2 PAN-OS 11.1 PAN-OS 10.2 Prisma Access | None < 12.1.4-h5, < 12.1.7 < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6 None | All >= 12.1.4-h5, >= 12.1.7 >= 11.2.4-h17, >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 >= 11.1.4-h33, >= 11.1.6-h32, >= 11.1.7-h6, >= 11.1.10-h25, >= 11.1.13-h5, >= 11.1.15 >= 10.2.7-h34, >= 10.2.10-h36, >= 10.2.13-h21, >= 10.2.16-h7, >= 10.2.18-h6 All | 2026-05-13 | 2026-05-28 |
| 6.1 | CVE-2026-0242
Trust Protection Foundation: SQL Injection Vulnerability | Trust Protection Foundation 25.3.0 Trust Protection Foundation 25.1.0 Trust Protection Foundation 24.3.0 Trust Protection Foundation 24.1.0 | < 25.3.3 < 25.1.8 < 24.3.6 < 24.1.13 | >= 25.3.3 >= 25.1.8 >= 24.3.6 >= 24.1.13 | 2026-05-13 | 2026-05-13 |
| 5.2 | CVE-2026-0244
Prisma SD-WAN: Improper Certificate Validation Vulnerability | Prisma SD-WAN ION 6.5 Prisma SD-WAN ION 6.4 Prisma SD-WAN ION 6.3 Prisma SD-WAN ION 6.1 Prisma SD-WAN ION 5.6 | < 6.5.3-b15 < 6.4.3-b8 < 6.3.6-b10 None None | >= 6.5.3-b15 >= 6.4.3-b8 >= 6.3.6-b10 All All | 2026-05-13 | 2026-05-13 |
| 4.5 | CVE-2026-0240
Trust Protection Foundation: Sensitive Information Disclosure Vulnerability | Trust Protection Foundation 25.3.0 Trust Protection Foundation 25.1.0 Trust Protection Foundation 24.3.0 Trust Protection Foundation 24.1.0 | < 25.3.3 < 25.1.8 < 24.3.6 < 24.1.13 | >= 25.3.3 >= 25.1.8 >= 24.3.6 >= 24.1.13 | 2026-05-13 | 2026-05-13 |